Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2019:2786-1

Опубликовано: 25 окт. 2019
Источник: suse-cvrf

Описание

Security update for docker-runc

This update for docker-runc fixes the following issues:

  • CVE-2019-16884: Fixed an LSM bypass via malicious Docker images that mount over a /proc directory. (bsc#1152308)

Список пакетов

Image SLES15-OCI-BYOS
docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.24.1
Image SLES15-SAP-OCI-BYOS
docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.24.1
Image SLES15-SP1-OCI-BYOS
docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.24.1
Image SLES15-SP1-SAP-OCI-BYOS
docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.24.1
Image SLES15-SP2-Azure-Basic
docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.24.1
Image SLES15-SP2-Azure-Standard
docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.24.1
Image SLES15-SP2-EC2-ECS-HVM
docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.24.1
Image SLES15-SP2-GCE
docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.24.1
Image SLES15-SP2-HPC-Azure
docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.24.1
SUSE Linux Enterprise Module for Containers 15
docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.24.1
SUSE Linux Enterprise Module for Containers 15 SP1
docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.24.1

Описание

runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.


Затронутые продукты
Image SLES15-OCI-BYOS:docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.24.1
Image SLES15-SAP-OCI-BYOS:docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.24.1
Image SLES15-SP1-OCI-BYOS:docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.24.1
Image SLES15-SP1-SAP-OCI-BYOS:docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.24.1

Ссылки